WhatsApp Us

Germany · DSGVO built in, not bolted on

GDPR compliant website for Germany: Impressum, consent and hosting done right from the first line of code

A GDPR compliant website in Germany needs more than a cookie banner: a complete Impressum under section 5 DDG, a privacy notice that matches what the site really does, consent under section 25 TDDDG with a reject option as easy as accept, fonts and media that do not leak visitor IP addresses, and hosting under a proper AVV. BtechWaleTech is three freelance developers in India who build all of that into new sites from US$150 and fix it on existing ones.

  • New website fromUS$150
  • Large SEO website fromUS$300
  • Build time1–2 weeks for a standard site
  • HostingEU server in your own account
  • Legal textsFrom your lawyer or legal-text service
  • Aftercare2 months free, then from US$120/mo
  • Impressum under § 5 DDG
  • Privacy notice matched to the site
  • Reject as easy as accept
  • Consent Mode v2
  • Self-hosted fonts
  • Consent-gated maps and video
  • EU hosting with AVV

Three freelance developers in India · English-speaking · replies on WhatsApp 7 days a week

  • 0Non-essential cookies before consent
  • 2Working days to an itemised quote
  • 2Months of free maintenance
  • 3Developers on your site

The short answer

What makes a GDPR compliant website in Germany?

A GDPR compliant website in Germany has a full Impressum, a privacy notice that lists every tool the site uses, no non-essential cookies or trackers before consent, a reject button as easy as accept, self-hosted fonts, consent-gated maps and videos, EU hosting with an AVV and secure forms. BtechWaleTech builds sites this way from US$150; your lawyer confirms the legal texts.

Online shops have extra duties, such as the new EU withdrawal button; and if your site sells to consumers, check the BFSG accessibility requirements too.

Last updated

GDPR website essentials in Germany
Provider identificationImpressum under section 5 DDG, reachable in one click
TransparencyPrivacy notice under Article 13 GDPR covering every tool actually used
Device accessConsent under section 25 TDDDG for anything not strictly necessary
Third-party contentFonts self-hosted; maps, video and chat only after consent
HostingEU data centre, AVV with the host
New siteFrom US$150, 1–2 weeks
Existing site fixAudit, then itemised quote for the fixes

What we build and fix

Privacy work built into every German website

These are built into new sites as standard, and each can be quoted as a fix for an existing site after a short technical audit.

New site with privacy by design

A fast site with no third-party requests before consent, self-hosted assets and clean forms, from US$150. Large content sites from US$300.

Technical GDPR audit

A scan of what your current site loads, sets and sends before and after consent, with every finding matched to a concrete fix and a price.

Consent banner and Consent Mode v2

A consent tool configured so tags stay off until consent, reject is as easy as accept, and Google tags receive the right consent signals.

Fonts, maps and video clean-up

Google Fonts moved to your server, maps and YouTube or Vimeo embeds replaced with click-to-load placeholders.

EU hosting move

Migration to an EU host or your own EU cloud account, with TLS, backups and access control, so your AVV covers the real setup.

WordPress and WooCommerce fixes

Plugin audit for hidden third-party calls, updates, and German shop compliance setup.

Shop compliance

Checkout, withdrawal and consent handling for Shopware and Shopify shops in Germany.

Care plan

Monthly updates, consent-tool checks after every new plugin or tag, and uptime monitoring from US$120/mo after the free period.

Why choose us

Ways to get a GDPR compliant website in Germany

Most German businesses choose one of these routes. Each can work; what matters is who checks what the site actually loads.

Ways to get a GDPR compliant website in Germany
Question Site builder plus plugin German web agency BtechWaleTech
Third-party requests before consent Often some, depending on template Depends on the agency's habits None by design; tested before launch
Fonts Often loaded from external servers Usually self-hosted Always self-hosted
Consent banner quality Plugin defaults Configured by the agency Configured and tested with reject flow
Hosting location Builder's servers, check the region Agency or your choice EU server in your account
Legal texts Generator or your lawyer Your lawyer or generator Your lawyer or legal-text service; we implement them
German-language support Varies Yes No; English, with German texts supplied by you
Who owns the site Tied to the builder Check the contract Domain, hosting and code in your name
Starting budget Low monthly fee Quotes vary widely From US$150

No developer can make a website legally compliant on their own; we build the technical side so compliance is possible, and your lawyer or data protection officer confirms the rest.

Pricing

What privacy work costs on a German website

On a new site, privacy by design is part of the build, not an extra: a standard site starts at US$150 and a large SEO site with 299+ pages at US$300. Fixing an existing site starts with a technical audit, then an itemised quote for each change. What moves the price: the number of third-party tools, plugins that load external resources, a shop checkout, tag management and Consent Mode, and whether a hosting move is needed. Legal texts come from your lawyer or a legal-text service and are not part of our price. Nothing is billed before you approve the quote.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What is a GDPR compliant website?

A GDPR compliant website is one whose data processing, from server logs and contact forms to cookies and embedded content, has a legal basis, is explained to visitors and is limited to what is needed. In Germany the GDPR is known as the DSGVO, and two national laws sit on top of it for websites: the Digital Services Act (DDG) for the Impressum and the TDDDG for access to visitors' devices.

Compliance is a property of the whole setup, not of a plugin. The same WordPress theme can be fine on one site and a problem on another, depending on which fonts it loads, which analytics tag was added later and whether the consent banner actually blocks anything. That is why a gdpr compliant website starts with a clear list of every request the page makes and every piece of data it stores.

It is also a shared job. The site owner is the controller and decides purposes, tools and texts. The developer builds the technical side so those decisions work: nothing loads before consent, forms collect only what is needed, logs are kept briefly. A lawyer or data protection officer confirms the legal side. We do the middle part carefully, and we never claim a site is "certified" GDPR compliant, because no such general certification for websites exists in the way that phrase suggests.

What does a website in Germany need to comply with the DSGVO?

In short: identification, transparency, consent where required, control over third parties, secure transmission and processors under contract. The list below is the technical and content checklist we work through on every German site.

  • Impressum under section 5 DDG, reachable from every page
  • Privacy notice (Datenschutzerklärung) describing every processing the site really performs
  • Consent under section 25 TDDDG before non-essential cookies, pixels or device storage
  • A reject option as easy to use as accept, and a way to change consent later
  • Fonts, icons and scripts hosted on your own server where possible
  • Maps, videos and social embeds loaded only after consent or a click
  • HTTPS everywhere, secure forms and short retention for submissions
  • Hosting and other processors under an AVV, with transfers outside the EU assessed

Every item has a technical side we build and a legal side you confirm. The sections below take them one by one. If you run an online shop, extra consumer-law duties apply; the Shopify developer page for Germany covers those for Shopify stores.

What must the Impressum contain under section 5 DDG?

The Impressum identifies who is behind a business website and how to reach them quickly. Since 14 May 2024 the obligation sits in section 5 of the Digitale-Dienste-Gesetz (DDG), which replaced the old Telemediengesetz; the content of the duty stayed the same, but references to "§ 5 TMG" are now outdated.

Typical contents include the full name and postal address of the provider (for companies, the legal form and authorised representatives), fast electronic contact such as an email address, the commercial register and number where registered, and the VAT identification number where one exists. Regulated professions and licensed activities have extra details, such as the chamber and professional rules. The exact wording for your business comes from your lawyer or a legal-text service.

The technical side is simple but often done badly. The Impressum must be easy to find and directly accessible, so we link it in the footer of every page, including checkout and landing pages, and never hide it behind a cookie banner that blocks the page. We do not put the email address in an image, because it must be usable. And we remove outdated "TMG" references during any rebuild, since they are an easy sign for a warning-letter writer that nobody has looked at the site in years.

What belongs in the Datenschutzerklärung of a GDPR compliant website?

The privacy notice explains, in plain language, who processes which data on the site, why, on what legal basis, with whom it is shared, for how long and what rights visitors have. Article 13 GDPR lists the information that must be given when data is collected.

The problem is rarely the template; it is the gap between the text and the site. A notice that mentions Google Analytics on a site that uses Matomo, or omits the newsletter tool, the booking widget and the chat plugin, is wrong in both directions. So before any text is written, we produce a technical inventory: every tool, what data it receives, where it processes that data and whether it needs consent. Your lawyer or legal-text generator then works from facts rather than guesses.

Each time a tool is added or removed, the notice must follow. That is why our care plan includes a check of the inventory whenever a plugin, tag or form changes. A gdpr compliant website at launch can drift out of compliance within a year simply because marketing added a new pixel through the tag manager without anyone updating the notice or the banner.

Storing information on a visitor's device, or reading information from it, needs consent unless it is strictly necessary for the service the visitor asked for. That is the core of section 25 TDDDG, which implements Article 5(3) of the ePrivacy Directive and refers to the GDPR's standard for valid consent.

Valid consent is informed, specific and freely given, and it is an active choice. Pre-ticked boxes do not count, and scrolling or continuing to browse is not consent. The German data protection authorities' guidance for digital services expects that, where visitors have to interact with a banner, declining must be as easy as accepting, which in practice means a reject button on the first layer next to accept, with equal visual weight.

Strictly necessary items, such as a session cookie for a shopping basket or storing the consent choice itself, do not need consent. Analytics, marketing pixels, A/B testing tools, embedded third-party content and most chat widgets usually do. We build so that those scripts are not in the page at all until consent is given, rather than loaded and then "told" not to track.

Visitors must also be able to change their mind as easily as they agreed. A persistent link such as "privacy settings" in the footer reopens the banner. The consent choice is logged in a way that lets you show what the visitor agreed to. The law text is published on gesetze-im-internet.de if you want to read it.

If you use Google Ads, Google Analytics or other Google tags for visitors in the EEA, yes. Since March 2024 Google has required advertisers serving EEA users to send consent signals, including the two newer parameters ad_user_data and ad_personalization, for measurement, remarketing and audience features to keep working for that traffic.

Consent Mode does not replace the consent banner; it passes the banner's result to Google tags. In "basic" mode, Google tags do not load at all until the visitor consents. In "advanced" mode, tags load before consent and send cookieless pings that Google uses for modelling. For German sites we recommend starting with basic mode, because it is the more cautious interpretation of section 25 TDDDG, and discussing advanced mode with your data protection officer if the marketing team needs it.

Technically, we configure the consent tool to set default consent states to "denied" before any Google tag runs, update them when the visitor chooses, and verify in the browser's developer tools and Google Tag Assistant that nothing fires early. That testing step is where many sites fail: a tag added directly in the theme bypasses the tag manager and the banner, and the gdpr compliant website quietly stops being one.

Why must Google Fonts be self-hosted on a German website?

Because loading fonts from Google's servers sends each visitor's IP address to Google, and a German court treated that as unlawful without consent. On 20 January 2022 the Regional Court of Munich I (LG München I, case 3 O 17493/20) ordered a website operator to stop disclosing a visitor's IP address through dynamically embedded Google Fonts and to pay damages of 100 euros.

The amount was small, but the ruling set off a wave of warning letters and compensation demands in 2022 against sites that still loaded fonts remotely. Many of those letters were later criticised as abusive, yet the simplest defence is not to be a target: host the font files on your own server, where no third party receives the request.

Self-hosting is easy and makes sites faster. We download the font files in the formats needed, serve them from your domain, and remove every remote reference, including ones buried in themes, page builders and plugins that pull fonts on their own. The same check covers icon fonts, JavaScript libraries loaded from public CDNs and any other resource fetched from a third-party server on page load. After the change we check the network tab to confirm no request leaves your domain before consent.

How can maps, YouTube and other embeds stay GDPR compliant?

Load them only after the visitor chooses to. A placeholder shows a static preview and a short note saying which provider will receive data; one click loads the real embed. Visitors who never click send nothing to Google, YouTube or Vimeo.

For maps, a static image of your location with a link to directions often does the job better than an interactive embed, and it needs no consent at all. Where an interactive map is needed, the placeholder approach works, or an OpenStreetMap-based map served through a provider you have an AVV with. For videos, the "privacy-enhanced mode" of YouTube reduces cookies but still contacts Google's servers, so it still belongs behind a click or consent. Self-hosting short videos on your own server avoids the question entirely.

Social media plugins, review widgets, booking tools and chat bubbles follow the same rule. Each one is a third party receiving data. We list them in the technical inventory, decide with you whether each is worth the consent friction, and build the click-to-load or consent-gated version for those you keep.

EU hosting and the AVV: what a GDPR compliant website needs

Your web host processes personal data on your behalf (at minimum IP addresses in server logs, usually form submissions and more), so Article 28 GDPR requires a data processing agreement, known in Germany as an Auftragsverarbeitungsvertrag or AVV. Most hosts offer a standard AVV in their customer panel; you conclude it in your own account.

We recommend hosting in an EU data centre, either with an EU hosting provider or in an EU region of a large cloud such as AWS Frankfurt, in an account owned by your company. That keeps the contract, the billing and the control with you, and it keeps the question of transfers outside the EU simple for the site itself.

Server logs deserve attention too. They are useful for security and debugging but contain IP addresses, so we set a short retention period and document it for your privacy notice. Backups follow the same logic: encrypted, in the EU, deleted on a schedule. The same applies to other processors in the chain, such as an email delivery service for forms or a newsletter tool; each needs its own AVV and belongs in your record of processing activities.

Can a GDPR compliant website use US tools under the EU-US Data Privacy Framework?

Yes, when the US provider is certified under the EU-US Data Privacy Framework and the use itself is lawful. The European Commission adopted its adequacy decision for the framework on 10 July 2023, and the EU General Court upheld it in 2025, so transfers to certified US organisations do not need Standard Contractual Clauses on top.

That solves the transfer question, not everything else. A US analytics or marketing tool still needs consent under section 25 TDDDG if it accesses the visitor's device, still has to appear in your privacy notice and still needs a processing agreement where it acts as a processor. And the certification must cover the specific company and the type of data; the Department of Commerce publishes the list of participants, which your data protection officer can check.

The framework could be challenged again in future, as its predecessors were. We therefore keep US tools optional wherever an EU alternative works equally well: privacy-friendly analytics hosted in the EU, forms processed on your own server, newsletters from an EU provider. That way a future court decision changes a few settings rather than the whole site. For transfers to India, which has no adequacy decision, see how offshore development handles GDPR; a website build itself does not require us to process your visitors' data.

How do German businesses avoid Abmahnungen over their website?

By removing the easy targets: missing or outdated Impressum details, trackers firing before consent, remote Google Fonts, a banner without a real reject option, missing privacy-notice entries and, for shops, consumer-law gaps. An Abmahnung is a formal warning letter, usually demanding a cease-and-desist declaration and costs, and website issues that anyone can detect with a browser are the most common triggers.

Warning letters about websites come from competitors, associations entitled to act, and sometimes individuals claiming GDPR damages. Whether a particular letter is justified, and how to respond, is a question for your lawyer; do not sign a cease-and-desist declaration without advice, because it can bind you for years.

What a developer can do is make the site boring to scan. We test every site before launch with a clean browser: what loads before any interaction, what happens on reject, whether any request goes to a third party, whether the Impressum and privacy notice are reachable from every page. We repeat that test after major changes. Most of the letters we have read about describe problems that would have failed this five-minute test, which is why a gdpr compliant website is mostly the result of routine rather than expensive tools.

Forms, newsletters and security on a GDPR compliant website

Collect only what you need, send it over HTTPS, store it briefly and protect it well. Forms are where visitors hand over personal data directly, so they deserve more care than any banner.

For contact forms, the mandatory fields should be the minimum you need to reply; everything else is optional. Submissions go by encrypted email or into a system with access control, not to a shared inbox everyone can read, and are deleted after the period you set. Spam protection works without third-party puzzles in most cases: honeypot fields and rate limits catch most bots, and if a CAPTCHA service is needed, it goes behind consent or uses a privacy-friendly provider.

Newsletters in Germany use double opt-in: the visitor subscribes, receives a confirmation email and only then is added, with the confirmation logged. We connect the form to your newsletter tool and make unsubscribing a single click.

Security is part of GDPR too: Article 32 asks for appropriate technical measures. For a website that means current software, strong admin passwords with two-factor login, minimal plugins, automatic backups and security headers. On WordPress sites, outdated plugins are the most common weak point, which is why updates are the first item in our care plans from US$120/mo.

How we build a GDPR compliant website from the start

We design the site so that, by default, it makes no request to any third party and stores nothing on the visitor's device except what is strictly necessary. Everything else is added deliberately, listed and gated.

In practice that means a technical inventory in week one, listing each planned tool with its purpose, data, location and consent status. Fonts and icons are self-hosted from the first template. Analytics is chosen with you: a privacy-friendly EU option, or Google Analytics with Consent Mode in basic mode. Embeds get click-to-load placeholders. Forms are built with minimal fields and a retention setting. Hosting is set up in your EU account with an AVV you conclude.

Before launch, we run the clean-browser test on every template, test accept, reject and change-of-mind flows, and hand you the inventory so your lawyer or legal-text service can write the privacy notice from facts. The Impressum and privacy notice are linked in every footer. Two months of free maintenance follow, during which any new tool goes through the same check. A new standard site starts at US$150; a large SEO site at US$300.

How to check if your existing website is GDPR compliant

Open the site in a private browser window with the developer tools' network tab open, and do nothing. Every request to a domain other than yours, and every cookie set before you click anything, is a finding to look at.

Then click reject and browse a few pages: nothing non-essential should appear. Click accept in a fresh window and compare. Check the footer for the Impressum and privacy notice on every page type, including the shop checkout and any landing pages built outside the main theme. Search the page source for "fonts.googleapis.com", "youtube.com/embed" and "maps.google" as quick indicators.

Our technical audit does the same systematically across all templates and adds the parts you cannot see from outside: plugin behaviour, server log retention, form storage, backups and hosting location. You receive a list of findings, each with the fix and its price, and decide what to do. We do not assess your legal texts or give legal opinions; findings about the texts are passed to your lawyer. If a relaunch is on the cards anyway, our website relaunch guide shows how to fix privacy gaps without losing rankings.

Building a GDPR compliant website with a team in India

A website build does not require us to handle your visitors' personal data, which keeps the data-protection side of working with a team abroad simple. We develop on a staging site with test content, and the live site runs on your EU hosting account.

Where we do need access to live data, for example to debug a form or maintain a shop with customer records, your data protection officer will usually want a processing agreement with us and Standard Contractual Clauses, because India has no EU adequacy decision. We keep that access minimal and through named accounts you can close at any time.

Day to day, your mornings overlap our afternoons: India is three and a half hours ahead of German summer time and four and a half in winter. In the first two weeks you can expect a kick-off call, the technical inventory for review, the first templates on staging and a demonstration of the consent flow. Quotes come itemised in USD within about two working days; invoices from India in USD or EUR are paid by Wise or bank wire; nothing is billed before your written approval. The domain, hosting and code are in your name.

We write in English. German legal texts come from your lawyer or a legal-text service, and German marketing copy from your team.

Worked example: a tax advisory office in Augsburg rebuilds its site

A hypothetical scenario, not a client case. Say a tax advisory office with 18 staff in Augsburg has a site built years ago on a page builder. It loads Google Fonts remotely, embeds a Google Map on the contact page, has an analytics tag in the theme header, a banner with only an "OK" button, an Impressum that still cites the TMG, and a contact form whose submissions land in a shared mailbox.

The rebuild would start with the inventory: fonts, map, analytics, form, a job application form, an appointment booking widget and the hosting provider, each with its data flow. The new site would self-host fonts, replace the map with a static image and a directions link, move analytics to an EU-hosted privacy-friendly tool that needs no consent in the office's chosen configuration (confirmed by its data protection officer), and put the booking widget behind a click.

Forms would send submissions encrypted to named recipients, applications would go to a separate address with a short retention period, and the banner would only appear if a consent-requiring tool remained. The Impressum would be updated to section 5 DDG, including the chamber details a tax adviser must give, with texts supplied by the office's legal-text service. Hosting would move to an EU host with an AVV.

Built as a standard site from US$150, the project would take about two weeks plus text delivery. The office would end up with fewer tools, a faster site and nothing for a scanner to flag.

GDPR compliant website checklist for Germany

Use this before launch and after every significant change. If any item fails, fix it before worrying about anything more advanced.

  • No third-party requests and no non-essential cookies before interaction
  • Reject button on the first banner layer, as prominent as accept
  • Consent can be changed from a link on every page
  • Google tags receive Consent Mode v2 signals, with default set to denied
  • Fonts, icons and scripts served from your own domain
  • Maps, videos and social embeds behind click-to-load placeholders
  • Impressum under section 5 DDG and privacy notice linked from every page
  • Privacy notice matches the current technical inventory
  • Hosting in the EU with an AVV concluded in your account
  • Forms minimal, over HTTPS, with a set retention period

Ten ticks do not replace legal advice, but they remove the issues most often found by automated scanners. Send us your URL on WhatsApp and we will tell you which items your current site fails.

Checklist

Website elements, the rule behind them and what we build

This supports your legal review and is not legal advice. Starting prices are on our pricing page.

Website elements, the rule behind them and what we build
ElementLegal hookWhat the build provides
Impressum Section 5 DDGFooter link on every page, text from your lawyer
Privacy notice Article 13 GDPRTechnical inventory as the factual basis
Cookie and device access Section 25 TDDDGScripts blocked until consent, equal reject
Google tags Google's EEA consent policyConsent Mode v2 with denied defaults
Fonts and assets GDPR, LG München I rulingSelf-hosted, no third-party requests
Hosting Article 28 GDPREU host, AVV in your account
Security Article 32 GDPRHTTPS, updates, backups, two-factor admin

Third-party content

How we handle common embeds on German sites

Some tools may be fine without consent in certain configurations; your data protection officer decides. For AI chat, see GDPR compliant AI chatbots.

How we handle common embeds on German sites
ToolDefault riskOur approach
Google Fonts IP sent to Google on page loadSelf-hosted font files
Google Maps Loads Google resourcesStatic image and link, or click-to-load
YouTube or Vimeo Contacts video platform on loadClick-to-load placeholder or self-hosted video
Analytics Device access, possible transfersEU-hosted option or consent-gated Google Analytics
reCAPTCHA Third-party scripts and dataHoneypot and rate limits first; consent if needed
Chat widgets Third-party scripts, stored messagesLoad after consent; AVV with provider
Social plugins Tracking by platformsPlain links instead of embedded buttons

Hosting and transfers

Where your site's data goes: three setups compared

Adequacy decisions and certifications can change; your data protection officer checks the current position.

Where your site's data goes: three setups compared
SetupTransfer mechanismWhat you still needOur view
EU host, EU tools only None neededAVVs, privacy notice, consent where requiredSimplest; our default
US tool certified under the DPF Adequacy decision of 10 July 2023Consent if device access, AVV, notice entryFine where no EU option fits
US tool not certified Standard Contractual Clauses plus assessmentTransfer impact assessment, AVV, consentAvoid for websites where possible
Developer access from India SCCs, since no adequacy decisionProcessing agreement if live data is accessedKeep access minimal and logged

Across Germany

German businesses we build privacy-first websites for

We work remotely for businesses anywhere in Germany. Each federal state has its own data protection authority for private businesses, but the rules for websites are the same nationwide.

  • Berlin

    Startups, agencies and online services in Berlin often run many marketing tools at once, which makes consent configuration and a clean technical inventory especially important.

  • Hamburg

    Trading firms, e-commerce brands and media companies in Hamburg rely on analytics and advertising, so Consent Mode v2 and a working reject flow matter for both compliance and measurement.

  • Munich

    Law firms, consultancies and tech companies in Munich expect privacy-first sites, and the Google Fonts ruling came from the city's own regional court.

  • Cologne and Bonn

    Insurers, associations and public-facing organisations along the Rhine need clear privacy notices, accessible forms and careful handling of embedded video content.

  • Frankfurt am Main

    Financial services firms and their suppliers want websites that send nothing to third parties by default and keep all hosting within the EU.

  • Stuttgart

    Engineering firms and suppliers in the Stuttgart region often have careers sections and RFQ forms that collect personal data and need short, documented retention.

  • Düsseldorf

    Advertising, fashion and consulting businesses in Düsseldorf use tracking-heavy marketing stacks that must be rebuilt around consent without losing measurement entirely.

  • Leipzig and Dresden

    Growing service businesses and online shops in Saxony often start on site builders and move to their own sites to control fonts, embeds and hosting.

  • Nuremberg

    Tax advisers, medical practices and IT firms in Nuremberg handle sensitive enquiries, so minimal contact forms and encrypted submission handling come first.

  • Augsburg

    Mid-sized manufacturers and professional practices in Augsburg frequently run older page-builder sites that still load fonts and maps from Google servers.

  • Hanover

    Insurers, trade-fair businesses and service companies in Hanover need event and booking pages whose third-party widgets are gated behind consent.

  • Bremen

    Logistics, food and maritime firms in Bremen increasingly recruit online, so application forms with secure storage and deletion schedules are a frequent request.

  • Münster

    Medical practices, law firms and associations in Münster want simple, fast sites with click-to-load maps and privacy notices that match what the site really does.

  • Mainz and Wiesbaden

    Public-facing organisations, media and pharma-adjacent businesses in the Rhine-Main area often need privacy work combined with accessibility improvements.

How it works

How we deliver a GDPR compliant website

  1. Share your URL or plan

    Send your current site or a description of the new one, plus the tools marketing and sales rely on, such as analytics, booking or newsletter software.

  2. Technical inventory

    We list every tool, what data it receives, where it processes it and whether it needs consent, and discuss alternatives where a tool causes more risk than value.

  3. Itemised quote

    Within about two working days: the build or fixes, hosting setup and any migration, priced in USD line by line. Nothing is billed until you approve in writing.

  4. Build with privacy defaults

    Fonts self-hosted, scripts gated, embeds behind placeholders, forms minimal and hosting set up in your EU account under the AVV you conclude.

  5. Clean-browser testing

    Every template is tested before interaction, after reject and after accept, and the inventory is handed to your lawyer or legal-text service for the texts.

  6. Launch and care

    The site goes live with Impressum and privacy notice linked everywhere, and two months of free maintenance follow. Care plans start from US$120/mo afterwards.

Questions

GDPR compliant website: questions from German businesses

What is a GDPR compliant website?

A GDPR compliant website processes visitors' personal data lawfully, transparently and minimally. In Germany that means a complete Impressum, a privacy notice matching the site's real tools, consent before non-essential cookies or trackers, controlled third-party content, secure forms and hosting under a proper processing agreement. The developer builds the technical side; your lawyer confirms the legal texts.

How much does a GDPR compliant website cost?

With BtechWaleTech, privacy by design is included in every build: a standard site starts at US$150 and a large SEO site with 299+ pages at US$300. Fixing an existing site starts with a technical audit and an itemised quote for each fix. Legal texts from your lawyer or a legal-text service are a separate cost.

Is a cookie banner enough to make my website GDPR compliant?

No. A banner only helps if it actually blocks scripts until consent and offers a reject option as easy as accept. You also need a correct Impressum, a privacy notice that matches the site, self-hosted fonts, consent-gated embeds, secure forms and a processing agreement with your host. Many sites with a banner still send data to third parties on page load.

Does my website need a reject button on the cookie banner?

Where visitors have to interact with the banner, German data protection authorities expect declining to be as easy as accepting, which in practice means a reject option on the first layer with equal prominence. Pre-ticked boxes and hidden reject links are common reasons banners are criticised. Your data protection officer can confirm the setup for your site.

What is section 25 TDDDG?

Section 25 of the Telecommunications Digital Services Data Protection Act requires consent before information is stored on, or read from, a user's device, unless it is strictly necessary for the service the user requested. It covers cookies, local storage, pixels and similar techniques. The law was called the TTDSG until May 2024, when it was renamed.

What must be in a German Impressum?

Typically the provider's full name and address, legal form and representatives for companies, a fast electronic contact such as an email address, the commercial register entry and VAT ID where available, and extra details for regulated professions. The obligation is in section 5 DDG, which replaced section 5 TMG in May 2024. Your lawyer should confirm the wording.

Can I use Google Fonts on a German website?

Load them from your own server, not Google's. In January 2022 the Regional Court of Munich I held that dynamically embedding Google Fonts without consent unlawfully disclosed a visitor's IP address and awarded damages of 100 euros. Self-hosting avoids the issue, speeds up the site and takes only a small amount of development work.

Can I embed Google Maps or YouTube videos?

Yes, if they load only after the visitor clicks or consents. We use placeholders that explain which provider receives data, and load the embed on click. For maps, a static image with a directions link often works just as well without consent. YouTube's privacy-enhanced mode still contacts Google, so it also belongs behind a click.

Do I need Google Consent Mode v2?

If you use Google Ads, Google Analytics or other Google tags for EEA visitors, Google has required consent signals since March 2024, including ad_user_data and ad_personalization. Consent Mode passes your banner's result to Google tags; it does not replace the banner. We recommend basic mode for German sites and testing that no tag fires before consent.

Does my website have to be hosted in Germany?

Not necessarily in Germany, but EU hosting is the simplest route, because it avoids transfer questions for the site itself. You need a processing agreement (AVV) with your host in any case. We set hosting up in an EU data centre, in an account owned by your company, and document log retention for your privacy notice.

Can I use US tools like Google Analytics under the Data Privacy Framework?

Transfers to US companies certified under the EU-US Data Privacy Framework are covered by the European Commission's adequacy decision of 10 July 2023, which the EU General Court upheld in 2025. That settles the transfer question, but device access still needs consent under section 25 TDDDG, and the tool must appear in your privacy notice.

What is an Abmahnung and how do I avoid one?

An Abmahnung is a formal warning letter, usually demanding a cease-and-desist declaration and costs. Website letters often target easily detected issues: trackers before consent, remote Google Fonts, missing Impressum details or banners without a real reject option. Fixing those removes the easiest targets. If you receive a letter, talk to your lawyer before signing anything.

Can you write my privacy notice and Impressum?

No, we do not write legal texts or give legal advice. We provide a technical inventory of every tool, data flow and retention period, which your lawyer or a legal-text service uses to write accurate texts, and we implement those texts on the site. That split keeps the legal content in the hands of people qualified to answer for it.

How do I check if my website is GDPR compliant?

Open it in a private browser window with the developer tools open and do nothing: any request to another domain or any cookie set before interaction is a finding. Then test reject and accept. Check that the Impressum and privacy notice are linked on every page. Our technical audit does this across all templates and adds server-side checks.

Is a WordPress website GDPR compliant?

WordPress can be, but themes and plugins often load external fonts, scripts or tracking by default, and outdated plugins create security risks. A plugin audit, self-hosted assets, a properly configured consent tool, updates and minimal plugins make the difference. Our WordPress developer page for Germany covers this in more detail.

Does a GDPR compliant website need double opt-in for newsletters?

Double opt-in is the standard practice in Germany: the subscriber confirms by clicking a link in an email before being added, and the confirmation is logged. It gives you evidence that the person really subscribed. We connect forms to your newsletter tool with double opt-in and one-click unsubscribe. Your lawyer confirms the consent wording.

Why work with a team in India on a GDPR compliant website?

The main reason is budget: privacy-first development usually costs less with a small remote team. A website build does not require access to your visitors' data, and your live site runs on EU hosting in your account. If we ever need access to live personal data, your data protection officer can set up the required agreement and SCCs first.

How do we communicate across time zones?

India is three and a half hours ahead of German summer time and four and a half hours ahead in winter, so your mornings overlap our afternoons every weekday. We use short video calls in that window, a staging site for reviews and WhatsApp or email for questions, answered seven days a week.

How is the work paid for?

You get an itemised quote in USD within about two working days and approve it in writing before anything is billed. Invoices come from India in USD or EUR and are paid by Wise or bank wire according to the schedule in the quote. Hosting is billed directly to you by your EU provider.

What happens after launch?

Two months of free maintenance cover updates and fixes, including checks whenever a new tool or plugin is added. After that, care plans start from US$120/mo and include updates, consent-tool checks and monitoring. Privacy compliance can drift as marketing adds tags, so a regular re-check is worth keeping.

Do online shops need extra measures beyond a GDPR compliant website?

Yes. Shops selling to consumers in Germany also need consumer-law elements such as a correctly labelled order button, withdrawal information and, since June 2026, an electronic withdrawal function, plus possibly BFSG accessibility duties. Payment and shipping providers add their own processing agreements. Our Shopware, Shopify and EU withdrawal button pages cover those areas.

Next step

Send us your URL for a privacy check

Share your current website or your plans on WhatsApp. You get an itemised quote in about two working days, with new privacy-first sites from US$150, EU hosting in your own account and a technical inventory your lawyer can work from.